Need Help? Contact support@mfasta.com

Privacy Policy

Last Updated: January 6, 2026

Introduction

By agreeing to this Privacy Policy, you acknowledge that you understand the features provided by the application and the necessary personal information required for the operation of these features, and you grant the corresponding authorization for collection and use. However, this does not mean that you have separately agreed to enable additional features, process non-essential personal information, or process sensitive personal information. We will separately seek your consent based on your actual usage for enabling additional features, processing non-essential personal information, and processing sensitive personal information.

I. How We Collect and Use Personal Information

In the process of using the "IFME CAM" software and services, we will collect information in accordance with the principles of legality, legitimacy, and necessity. The information we collect or request you to provide will be used for:

  1. Ensuring the basic normal operation of the product;
  2. Realizing various functions and services;
  3. Optimizing and improving products and services;
  4. Ensuring the security of products, services, and user usage;
  5. Complying with laws, regulations, and national standards.

We will collect information that you actively provide when using the service, as well as information generated during your use of functions or acceptance of services, in the following ways:

1. Providing Photography Features

When you use "IFME CAM" and related services:

  1. Camera/camera permission is required for taking photos and recording videos. Please note that even if you have agreed to enable camera/camera permission, we will only use the camera/camera to obtain information when taking photos, recording videos, etc.
  2. Album or storage permission is required to save photos and videos to the album.
  3. Location information permission is required to write location information into photos and videos.
  4. We will collect your hardware model, operating system version number, software version number, device information (Android ID, OAID, MAC address, sensor information (gyroscope, gravity, orientation, acceleration, linear acceleration)), and other information. Please understand that this information is essential basic information that we must collect to provide services and ensure the normal operation of the product.

2. Logging into "IFME CAM" and Related Services

You can choose to use Apple account authorization to log in to "IFME CAM". This information is only used for login-related purposes.

3. Message Notifications

When "IFME CAM" releases new services or features, we may also send service information to you through pop-ups or push notifications. If you do not wish to receive our product or service information, you can turn off the push notification function of "IFME CAM" in the system settings.

4. Ensuring Product, Service, and User Usage Security

To help us better understand the operation of "IFME CAM" and related services, so as to ensure the security of operation and service provision, we may record network log information (including purchase records, download records, IP address, client type, system type, system version, phone model, language used, access date and time), as well as information such as the frequency of using software and related services, crash data, overall installation, usage, and performance data.

II. Use of Cookies and Similar Technologies

Cookies and similar technologies are common technologies on the Internet. When you use "IFME CAM" software and related services, we may use related technologies to send one or more cookies or anonymous identifiers to your device to collect and store information when you access and use this product. We may set cookies or anonymous identifiers for authentication and security purposes to ensure the safe and efficient operation of products and services, help us improve service efficiency, and enhance login and response speed.

III. Entrusted Processing

We may entrust authorized partners to process your personal information so that authorized partners can provide certain services or perform functions on our behalf. We will only entrust them to process your information for the legal, legitimate, necessary, specific, and clear purposes stated in this policy. Authorized partners can only access the information necessary for them to perform their duties, and we will require them through agreements not to use this information for any purpose beyond the scope of the entrustment. If authorized partners use your information for purposes we have not entrusted, they will separately obtain your consent.

Currently, our authorized partners include the following types:

Suppliers, service providers, and other partners. We entrust information to suppliers, service providers, and other partners who support our business. This support includes technical infrastructure services provided on our behalf, analyzing how our services are used, providing customer service, payment convenience, or conducting academic research and investigations.

To ensure the stable operation and functional implementation of our client, and to enable you to use and enjoy more services and functions, our application will embed SDKs or similar applications from authorized partners. We will conduct strict security inspections on the application programming interfaces (APIs) and software development kits (SDKs) used by authorized partners to obtain relevant information, and agree on strict data protection measures with authorized partners, requiring them to process personal information in accordance with this policy and any other relevant confidentiality and security measures.

IV. How We Store Personal Information

(1) Location of Information Storage

The personal information we collect and generate in our operations will be stored in regions that comply with applicable laws and regulations. Under the following circumstances, we will provide your personal information to possible overseas entities after fulfilling our legal obligations:

  1. Applicable laws have clear provisions;
  2. We have obtained your separate consent;
  3. It is necessary for cross-border e-commerce transactions and other types of contract conclusion and performance in which you are a party.

For the above circumstances, we will protect your personal information security in accordance with this policy and applicable laws.

(2) Storage Period

We will only retain your personal information for the period necessary to achieve the purposes stated in this policy, unless the law has mandatory retention requirements, such as requiring that product and service information and transaction information be retained for no less than three years from the date of transaction completion according to the statute of limitations and other provisions.

We determine the storage period of personal information mainly based on the following criteria:

  1. Completing transaction purposes related to you, maintaining corresponding transaction and business records, to respond to your possible inquiries or complaints;
  2. Ensuring the security and quality of the services we provide to you;
  3. Whether you agree to a longer retention period;
  4. Whether there are other special agreements or legal provisions regarding the retention period.

After the retention period expires, we will delete or anonymize your personal information in accordance with applicable legal requirements.

(3) Storage Security

  1. Technical Measures for Data Protection

We have adopted security protection measures that comply with industry standards and are reasonably feasible to protect your information, preventing personal information from unauthorized access, public disclosure, use, modification, damage, or loss. For example, we will use encryption technology to improve the security of personal information. Data exchanged between your browser and server is protected by SSL protocol encryption, and we provide HTTPS protocol for secure browsing. We will use trusted protection mechanisms to prevent personal information from malicious attacks. We will deploy access control mechanisms to ensure that only authorized personnel can access personal information.

  1. Organizational Measures for Data Protection Management

We have established an advanced data security management system in the industry that is data-centric and revolves around the data lifecycle, improving the security of personal information from the dimensions of organizational construction, system design, personnel management, and product technology. We have set up a dedicated department for personal information protection and appointed a person in charge of personal information protection. We continuously strengthen employees' awareness of the importance of protecting personal information through training courses and examinations.

  1. Response to Personal Information Security Incidents

If our physical, technical, or management protection facilities are damaged, resulting in unauthorized access, public disclosure, tampering, or destruction of information, causing damage to your legitimate rights and interests, we will promptly activate emergency plans and take reasonable and necessary measures to minimize the impact on you. If a personal information security incident occurs, we will also inform you of the basic situation and possible impact of the security incident, the measures we have taken or will take, suggestions for you to prevent and reduce risks independently, and remedial measures for you in accordance with legal requirements. We will inform you through SMS, phone calls, push notifications, and other reasonable channels. If it is difficult to inform you one by one, we will publish announcements in a reasonable and effective manner. At the same time, we will also report the handling of personal information security incidents to regulatory authorities as required.

  1. Prevention of Account Security Risks

Please properly protect your personal information and only provide it to others when necessary. Do not trust transactions through other trading tools to avoid information theft or even telecommunications network fraud.

If you are concerned that your personal information, especially your account or password, has been leaked, please contact us immediately through the contact information of the person in charge of personal information protection published in this privacy policy so that we can take corresponding measures according to your application.

V. How We Share, Transfer, and Publicly Disclose Personal Information

We will not share, transfer, or publicly disclose your personal information to third parties unless you have given prior authorization and consent, or the shared, transferred, or publicly disclosed personal information is anonymized information, and third parties cannot re-identify natural persons based on such information.

We will carefully evaluate the purpose of third parties' use of shared information, comprehensively assess the security assurance capabilities of these partners, and require them to comply with cooperative legal agreements. We will conduct strict security monitoring on the software development kits (SDKs) and application programming interfaces (APIs) used by partners to obtain information to protect data security.

1. Sharing with Third Parties to Realize Related Functions or Services

When you use payment function services provided by third-party payment companies, third-party payment companies need to collect your name, bank card type and number, validity period, and mobile phone number. The above information is sensitive personal information. Refusing to provide such information will only prevent you from using this function, but will not affect your normal use of other functions.

2. Transfer of Personal Information in Case of Acquisition, Merger, and Reorganization

As our business continues to develop, we may engage in mergers, acquisitions, and asset transfers, and your personal information may be transferred as a result. When the aforementioned changes occur, we will continue to protect or require the successor of personal information to continue to protect your personal information in accordance with laws and regulations and security standards no lower than those required by this privacy policy. Otherwise, we will require the successor to re-obtain your authorization and consent.

3. Statutory Circumstances Where Consent Is Not Required for Sharing, Transferring, and Publicly Disclosing Personal Information

According to applicable laws and regulations, in the following circumstances, we do not need to obtain your prior consent to share, transfer, or publicly disclose your personal information:

  1. Related to our fulfillment of obligations stipulated by laws and regulations;
  2. Directly related to national security and defense security;
  3. Directly related to public safety, public health, and major public interests;
  4. Directly related to criminal investigation, prosecution, trial, and execution of judgments;
  5. Necessary to protect your or others' major legitimate rights and interests such as life and property, but it is difficult to obtain your authorization and consent;
  6. Personal information that you have publicly disclosed to the public;
  7. Collecting personal information from legally publicly disclosed information, such as legal news reports, government information disclosure, and other channels.

4. Cessation of Operations

If we cease operations of products and/or services, we will promptly stop collecting your personal information. We will send notifications one by one or inform you of the cessation of operations in the form of announcements, and delete or anonymize the personal information we hold related to the discontinued products and/or services.

5. Circumstances Where Authorization and Consent Are Exempted According to Law

Please understand that in the following circumstances, according to laws, regulations, and national standards, partners' use, or our transfer or disclosure of your personal information does not require your authorization and consent:

  1. Necessary for concluding or performing a contract at your request;
  2. Necessary for fulfilling legal duties or legal obligations: We may share your personal information in accordance with legal provisions, the necessity of litigation and dispute resolution, or requirements put forward by administrative and judicial organs in accordance with the law, and other necessities for fulfilling legal obligations;
  3. Necessary to respond to public health emergencies or to protect the life, health, and property safety of natural persons in emergency situations;
  4. Processing personal information within a reasonable scope for the public interest, such as news reporting and public opinion supervision;
  5. Processing personal information that you have publicly disclosed or other legally publicly disclosed personal information (such as personal information legally disclosed through legal news reports, government information disclosure, and other channels) within a reasonable scope;
  6. Other circumstances stipulated by laws and regulations.

VI. How We Protect Personal Information Security

  1. We attach great importance to the security of your personal information and will make every effort to take reasonable security measures (including technical and management aspects) to protect your personal information, preventing your personal information from being improperly used or accessed, publicly disclosed, used, modified, damaged, lost, or leaked without authorization.
  2. We will use encryption technology, anonymization processing, and other reasonably feasible means that are no less than industry peers to protect your personal information, and use security protection mechanisms to prevent your personal information from malicious attacks.
  3. We will establish specialized security departments, security management systems, and data security processes to ensure the security of your personal information. We adopt strict data use and access systems to ensure that only authorized personnel can access your personal information, and conduct security audits on data and technology in a timely manner.
  4. Although we have taken the above reasonable and effective measures and have complied with the standards required by relevant legal provisions, please understand that due to technical limitations and possible various malicious means, in the Internet industry, even if we do our best to strengthen security measures, it is impossible to always guarantee 100% security of information. We will do our best to ensure the security of the personal information you provide to us. You know and understand that the systems and communication networks you use to access our services may have problems due to factors beyond our control. Therefore, we strongly recommend that you take active measures to protect the security of personal information.
  5. We will formulate emergency response plans and immediately activate emergency plans when user information security incidents occur, striving to prevent the impact and consequences of such security incidents from expanding. Once a user information security incident (leakage, loss, etc.) occurs, we will inform you in a timely manner in accordance with legal requirements: the basic situation and possible impact of the security incident, the measures we have taken or will take, suggestions for you to prevent and reduce risks independently, and remedial measures for you. We will inform you of the relevant situation of the incident in a timely manner through push notifications, emails, letters, SMS, and other forms. When it is difficult to inform you one by one, we will publish announcements in a reasonable and effective manner. At the same time, we will also report the handling of user information security incidents to relevant regulatory authorities as required.
  6. We hereby specifically remind you that the personal information protection measures provided in this privacy policy only apply to the "IFME CAM" software and related services. Once you leave "IFME CAM" and related services, browse or use other websites, services, and content resources, we have no ability or obligation to protect any personal information you submit on software and websites other than "IFME CAM" software and related services, regardless of whether you log in, browse, or use the above software and websites based on links or guidance from "IFME CAM".

VII. Your Rights

(1) Query and Copy Your Information

You can query and copy your personal information within the application.

(2) Change Your Information

You can directly change your contact information in "IFME CAM" through the account settings function in the application.

(3) Delete Your Information

You can delete your account on "IFME CAM" by sending an email to the personal information protection officer's email address: support@mfasta.com. Before deleting your account, we will reply to you within 15 business days and verify your personal identity, security status, device information, etc., and reply and process after confirming the above information. You know and understand that account deletion is an irreversible action. Once you delete your account, we will stop providing you with related services.

VIII. Minor Provisions

If you are a minor under 18 years of age, you should read and agree to this privacy policy together with your parents or other guardians under their supervision and guidance before using the "IFME CAM" software and related services.

We protect minors' personal information in accordance with applicable laws and regulations, and will only collect, use, share, or disclose minors' personal information when permitted by law, with the explicit consent of parents or other guardians, or when necessary to protect minors. If we find that we have collected minors' personal information without prior verifiable parental consent, we will try to delete the relevant information as soon as possible.

If you are a guardian of a minor, when you have questions about the personal information of the minor under your guardianship, please contact us through the contact information of the personal information protection officer published in this privacy policy.

IX. Revision and Notification of Privacy Policy

In order to provide you with better services, the "IFME CAM" software and related services will be updated and changed from time to time. We will revise this privacy policy in a timely manner. Such revisions constitute part of this privacy policy and have the same effect as this privacy policy. However, without your explicit consent, we will not reduce the rights you should enjoy under the currently effective privacy policy.

For major changes, we will also provide more prominent notifications (including notifications through announcements or pop-up prompts).

The major changes referred to in this policy include but are not limited to:

  1. Major changes in the business model of the product, such as the purpose of processing personal information, the types of personal information processed, and the way personal information is used;
  2. Changes in the subject of the privacy policy caused by business adjustments, transaction mergers and acquisitions, and changes in the processing purposes and methods of the new subject recipient;
  3. Changes in the main objects of personal information sharing or public disclosure;
  4. Major changes in users' personal information rights and how they are exercised;
  5. Changes in the contact information of the person in charge of personal information protection and complaint channels;
  6. When the personal information protection impact assessment report indicates that the product has a significant impact on personal rights and interests.

X. How to Contact Us

If you have any questions, comments, or suggestions about the content of this policy, or any questions about personal information protection, you can contact us by sending an email to the personal information protection officer's email address: support@mfasta.com. Generally, we will reply to you within 15 business days.

XI. Others

  1. The headings in this "Privacy Policy" are for convenience and reading only and do not affect the meaning or interpretation of any provisions in this privacy policy.

  2. Definitions of related terms in this "Privacy Policy":

  3. "IFME CAM" software and related services refer to products and services provided to you by MFASTA Inc and its affiliates through legally owned and operated client applications labeled "IFME CAM".

  4. Affiliates refer to any company, institution, and the legal representative of the above companies or institutions that are now or will be controlled by, controlled by, or under common control with one party. "Control" means the ability to directly or indirectly influence the management of the mentioned company, whether through ownership, voting shares, contracts, or other legally recognized means.

If you have any questions, please contact: support@mfasta.com